nftables section
This commit is contained in:
@@ -75,6 +75,147 @@ A transparent inline bridge occupies the forwarding path without acting as an \a
|
||||
|
||||
Transparency should not be understood as complete undetectability. An inline bridge can affect latency, packet ordering, loss behavior, link-state propagation, and bridge-control behavior. If \ac{STP} is enabled, \acp{BPDU} and forwarding-delay behavior may become externally visible \cite{linuxkernelbridgedocs}. If \ac{TLS} proxying is added on top of forwarding, certificate and handshake artifacts can reveal the interception point \cite{durumeric2017httpsinterception}. The transparency goal in this thesis is therefore narrower and technical: the system should forward traffic as a Layer-2 inline bridge without introducing an additional \ac{IP} hop, without requiring endpoint proxy configuration, and without terminating application-layer sessions unless a later manipulation component explicitly does so.
|
||||
|
||||
\section{Linux Packet Filtering with \texttt{nftables}}
|
||||
\label{sec:nftables}
|
||||
|
||||
% cites noch ergänzen: nftables_manpage und nf queue noch
|
||||
|
||||
\texttt{nftables} is a framework for packet filtering and classification in Linux.
|
||||
The \texttt{nft} command-line tool is used to set up, maintain, and inspect packet-filtering and classification rules in the Linux kernel.
|
||||
The corresponding Linux kernel subsystem is called \texttt{nf\_tables} and is part of Netfilter.
|
||||
|
||||
An \texttt{nftables} ruleset is organized using several types of objects.
|
||||
In particular, \textbf{tables} are containers for chains, sets, and stateful objects, while \textbf{chains} are containers for rules.
|
||||
Tables are identified by an address family and a name.
|
||||
The supported table families are \texttt{ip}, \texttt{ip6}, \texttt{inet}, \texttt{arp}, \texttt{bridge}, and \texttt{netdev}.
|
||||
If no family is specified, the \texttt{ip} family is used by default.
|
||||
|
||||
|
||||
\subsection{Address Families and Hooks}
|
||||
\label{sec:nftables-address-families}
|
||||
|
||||
Address families determine the type of packets that \texttt{nftables} processes.
|
||||
For each address family, the kernel provides hooks at particular stages of the packet-processing path.
|
||||
These hooks invoke \texttt{nftables} when rules for the respective hooks exist.
|
||||
The \texttt{ip} family processes IPv4 packets, \texttt{ip6} processes IPv6 packets, and \texttt{inet} provides a combined IPv4/IPv6 family.
|
||||
The \texttt{arp} family handles IPv4 ARP packets, the \texttt{bridge} family handles packets traversing a bridge device, and the \texttt{netdev} family handles packets on the ingress and egress paths.
|
||||
\texttt{nftables} objects exist in address-family-specific namespaces.
|
||||
|
||||
For the IPv4, IPv6, and \texttt{inet} address families, \texttt{nftables} defines hooks at different stages of packet processing.
|
||||
The \texttt{prerouting} hook processes packets entering the system before the routing process.
|
||||
Packets delivered to the local system are processed by the \texttt{input} hook, while packets forwarded to another host are processed by the \texttt{forward} hook.
|
||||
Packets generated by local processes pass through the \texttt{output} hook, and packets leaving the system pass through the \texttt{postrouting} hook.
|
||||
The \texttt{inet} family additionally supports an \texttt{ingress} hook, which is invoked before the Layer-3 protocol handlers and therefore before \texttt{prerouting}.
|
||||
|
||||
The \texttt{bridge} address family handles Ethernet packets traversing bridge devices.
|
||||
According to the \texttt{nftables} documentation, its list of supported hooks is identical to that of the IPv4, IPv6, and \texttt{inet} families described above.
|
||||
|
||||
|
||||
\subsection{Tables, Chains, and Rules}
|
||||
\label{sec:nftables-tables-chains-rules}
|
||||
|
||||
Chains exist in two forms: base chains and regular chains.
|
||||
A base chain is an entry point for packets from the networking stack.
|
||||
A regular chain can be used as a jump target and for organizing rules.
|
||||
When a chain is created with a hook and priority, it becomes a base chain and is connected to the networking stack.
|
||||
For base chains, the chain type, hook, and priority parameters are mandatory.
|
||||
|
||||
The \texttt{filter} chain type is supported by all families and hooks.
|
||||
Other chain types have additional restrictions.
|
||||
For example, \texttt{nat} chains are supported by the \texttt{ip}, \texttt{ip6}, and \texttt{inet} families, while \texttt{route} chains are restricted to the \texttt{output} hook of those families.
|
||||
|
||||
A base chain has a priority that determines its evaluation order relative to other chains attached to the same hook.
|
||||
Lower numerical priority values are evaluated before higher values.
|
||||
The evaluation order of chains with identical priorities is undefined.
|
||||
\texttt{nftables} provides names for several standard priority values, and the priority values used by the \texttt{bridge} family differ from those used by the other families.
|
||||
|
||||
For the \texttt{bridge} family, the predefined priorities include \texttt{dstnat} with a value of $-300$ for \texttt{prerouting}, \texttt{filter} with a value of $-200$ for all hooks, \texttt{out} with a value of $100$ for \texttt{output}, and \texttt{srcnat} with a value of $300$ for \texttt{postrouting}.
|
||||
|
||||
A base chain can also specify a policy.
|
||||
The supported policies are \texttt{accept} and \texttt{drop}, with \texttt{accept} being the default.
|
||||
The policy determines what happens to packets for which the rules in the chain do not explicitly produce an acceptance or refusal.
|
||||
|
||||
Rules are contained within chains.
|
||||
According to the \texttt{nftables} documentation, rules consist of two types of components: expressions and statements.
|
||||
|
||||
|
||||
\subsection{Expressions and Statements}
|
||||
\label{sec:nftables-expressions-statements}
|
||||
|
||||
Expressions represent values.
|
||||
These values may be constants, such as network addresses and port numbers, or information obtained from a packet during ruleset evaluation.
|
||||
Expressions can be combined to construct match expressions and can also be used as arguments for operations such as NAT or packet marking.
|
||||
Each expression has a data type that determines properties including its size, parsing, representation, and compatibility with other expressions.
|
||||
|
||||
\texttt{nftables} provides, among others, meta expressions and payload expressions.
|
||||
A meta expression accesses metadata associated with a packet.
|
||||
Available metadata includes the packet length, protocol family, Layer-4 protocol, packet mark, input and output interfaces, and packet type.
|
||||
|
||||
The input and output interfaces can be accessed using \texttt{iif}, \texttt{oif}, \texttt{iifname}, and \texttt{oifname}.
|
||||
\texttt{iif} and \texttt{oif} operate on interface indices, whereas \texttt{iifname} and \texttt{oifname} operate on interface names.
|
||||
\texttt{nftables} also provides \texttt{ibrname} and \texttt{obrname}, representing the input and output bridge interface names, respectively.
|
||||
|
||||
Payload expressions refer to information contained in a packet's payload.
|
||||
For Ethernet headers, \texttt{nftables} provides expressions for the destination address (\texttt{ether daddr}), source address (\texttt{ether saddr}), and EtherType (\texttt{ether type}).
|
||||
|
||||
Further payload expressions provide access to fields of higher-layer protocols.
|
||||
For example, IPv4 expressions can access fields including source and destination addresses and the upper-layer protocol, while IPv6 expressions provide access to fields including source and destination addresses and the next-header field.
|
||||
TCP and UDP expressions provide access to source and destination ports as well as additional protocol-specific header fields.
|
||||
|
||||
Statements represent actions that are performed during rule evaluation.
|
||||
They may alter the control flow by accepting or dropping a packet or by transferring evaluation to another chain.
|
||||
Statements may also perform other actions, including logging and rejecting packets.
|
||||
nftables distinguishes between terminal and non-terminal statements.
|
||||
Terminal statements unconditionally terminate evaluation of the current rule, whereas non-terminal statements either conditionally terminate evaluation or allow it to continue.
|
||||
|
||||
|
||||
\subsection{Ruleset Evaluation and Verdicts}
|
||||
\label{sec:nftables-ruleset-evaluation}
|
||||
|
||||
Packets traverse the networking stack and are evaluated by base chains attached to the hooks they encounter.
|
||||
If multiple base chains are attached to the same hook, the chains are evaluated according to their priorities, with lower priority values evaluated first.
|
||||
Base chains may call regular chains using \texttt{jump} and \texttt{goto}, and regular chains may in turn call other regular chains.
|
||||
Chains in different tables cannot call each other.
|
||||
|
||||
nftables provides the verdict statements \texttt{accept}, \texttt{drop}, \texttt{continue}, \texttt{return}, \texttt{jump}, and \texttt{goto}.
|
||||
The \texttt{accept} and \texttt{drop} verdicts terminate chain evaluation, but their effects on subsequent processing differ.
|
||||
|
||||
An \texttt{accept} verdict terminates evaluation of the current base chain.
|
||||
Processing can subsequently continue in another base chain attached to the same hook or in a base chain attached to a later hook.
|
||||
Consequently, a packet that receives an \texttt{accept} verdict may still subsequently receive a \texttt{drop} verdict from another base chain.
|
||||
|
||||
A \texttt{drop} verdict immediately drops the packet and terminates evaluation of the ruleset.
|
||||
No further chains are evaluated, and the verdict cannot be overridden by a later \texttt{accept} verdict.
|
||||
|
||||
The \texttt{jump} statement stores the current evaluation position and continues evaluation at the beginning of another regular chain.
|
||||
When that chain ends, evaluation can return to the stored position.
|
||||
\texttt{goto} similarly transfers evaluation to another chain but does not store the current position.
|
||||
\texttt{return} terminates evaluation of the current chain and, where a stored position exists, continues evaluation from that position.
|
||||
|
||||
|
||||
\subsection{Queueing Packets to Userspace}
|
||||
\label{sec:nftables-queue}
|
||||
|
||||
In addition to issuing verdicts directly in the ruleset, nftables provides a \texttt{queue} statement.
|
||||
The \texttt{queue} statement passes a packet to userspace using the \texttt{nfnetlink\_queue} handler.
|
||||
The packet is placed into a queue identified by a 16-bit queue number.
|
||||
The default queue number is 0.
|
||||
|
||||
A userspace application receiving a queued packet can inspect it and may optionally modify it.
|
||||
The userspace application must subsequently provide either an \texttt{accept} or a \texttt{drop} verdict.
|
||||
If the packet is accepted, nftables processing resumes with the next base-chain hook rather than with the rule following the \texttt{queue} statement.
|
||||
The nftables documentation refers to the \texttt{libnetfilter\_queue} documentation for further details concerning userspace queue processing.
|
||||
|
||||
The \texttt{queue} statement can specify a single queue number, a range of queue numbers, or an expression that determines the queue number.
|
||||
Queue numbers may be computed at runtime using \texttt{numgen}, \texttt{hash}, or \texttt{symhash} expressions, and a map statement can be used to select fixed queue numbers based on inputs such as source IP addresses or interface names.
|
||||
|
||||
Two flags are defined for the \texttt{queue} statement: \texttt{bypass} and \texttt{fanout}.
|
||||
The \texttt{fanout} flag distributes packets between several queues.
|
||||
The \texttt{bypass} flag allows packets to proceed when the userspace application cannot process them; the documentation recommends consulting the \texttt{libnetfilter\_queue} documentation for performance-tuning recommendations before using this flag.
|
||||
```
|
||||
consulting the \texttt{libnetfilter\_queue} documentation for performance-tuning recommendations before using this flag.
|
||||
|
||||
|
||||
\section{Linux Packet Processing Path}
|
||||
\label{sec:linux-packet-processing-path}
|
||||
|
||||
|
||||
@@ -1,316 +1,326 @@
|
||||
@article{cerf1974protocol,
|
||||
author = {Cerf, Vinton G. and Kahn, Robert E.},
|
||||
title = {A Protocol for Packet Network Intercommunication},
|
||||
author = {Cerf, Vinton G. and Kahn, Robert E.},
|
||||
title = {A Protocol for Packet Network Intercommunication},
|
||||
journaltitle = {IEEE Transactions on Communications},
|
||||
volume = {22},
|
||||
number = {5},
|
||||
pages = {637--648},
|
||||
date = {1974-05},
|
||||
doi = {10.1109/TCOM.1974.1092259}
|
||||
volume = {22},
|
||||
number = {5},
|
||||
pages = {637--648},
|
||||
date = {1974-05},
|
||||
doi = {10.1109/TCOM.1974.1092259}
|
||||
}
|
||||
|
||||
@techreport{rfc791,
|
||||
author = {Postel, Jon},
|
||||
title = {Internet Protocol},
|
||||
type = {RFC},
|
||||
number = {791},
|
||||
author = {Postel, Jon},
|
||||
title = {Internet Protocol},
|
||||
type = {RFC},
|
||||
number = {791},
|
||||
institution = {RFC Editor},
|
||||
date = {1981-09},
|
||||
doi = {10.17487/RFC0791}
|
||||
date = {1981-09},
|
||||
doi = {10.17487/RFC0791}
|
||||
}
|
||||
|
||||
@techreport{rfc793,
|
||||
author = {Postel, Jon},
|
||||
title = {Transmission Control Protocol},
|
||||
type = {RFC},
|
||||
number = {793},
|
||||
author = {Postel, Jon},
|
||||
title = {Transmission Control Protocol},
|
||||
type = {RFC},
|
||||
number = {793},
|
||||
institution = {RFC Editor},
|
||||
date = {1981-09},
|
||||
doi = {10.17487/RFC0793}
|
||||
date = {1981-09},
|
||||
doi = {10.17487/RFC0793}
|
||||
}
|
||||
|
||||
@techreport{rfc1122,
|
||||
author = {Braden, Robert},
|
||||
title = {Requirements for Internet Hosts -- Communication Layers},
|
||||
type = {RFC},
|
||||
number = {1122},
|
||||
author = {Braden, Robert},
|
||||
title = {Requirements for Internet Hosts -- Communication Layers},
|
||||
type = {RFC},
|
||||
number = {1122},
|
||||
institution = {RFC Editor},
|
||||
date = {1989-10},
|
||||
doi = {10.17487/RFC1122}
|
||||
date = {1989-10},
|
||||
doi = {10.17487/RFC1122}
|
||||
}
|
||||
|
||||
@techreport{rfc1812,
|
||||
author = {Baker, Fred},
|
||||
title = {Requirements for {IP} Version 4 Routers},
|
||||
type = {RFC},
|
||||
number = {1812},
|
||||
author = {Baker, Fred},
|
||||
title = {Requirements for {IP} Version 4 Routers},
|
||||
type = {RFC},
|
||||
number = {1812},
|
||||
institution = {RFC Editor},
|
||||
date = {1995-06},
|
||||
doi = {10.17487/RFC1812}
|
||||
date = {1995-06},
|
||||
doi = {10.17487/RFC1812}
|
||||
}
|
||||
|
||||
@techreport{rfc3022,
|
||||
author = {Srisuresh, Pyda and Egevang, Kjeld},
|
||||
title = {Traditional {IP} Network Address Translator ({Traditional NAT})},
|
||||
type = {RFC},
|
||||
number = {3022},
|
||||
author = {Srisuresh, Pyda and Egevang, Kjeld},
|
||||
title = {Traditional {IP} Network Address Translator ({Traditional NAT})},
|
||||
type = {RFC},
|
||||
number = {3022},
|
||||
institution = {RFC Editor},
|
||||
date = {2001-01},
|
||||
doi = {10.17487/RFC3022}
|
||||
date = {2001-01},
|
||||
doi = {10.17487/RFC3022}
|
||||
}
|
||||
|
||||
@inproceedings{stephan2024packetpath,
|
||||
author = {Stephan, Alexander and W{\"u}strich, Lars},
|
||||
title = {The Path of a Packet Through the Linux Kernel},
|
||||
author = {Stephan, Alexander and W{\"u}strich, Lars},
|
||||
title = {The Path of a Packet Through the Linux Kernel},
|
||||
booktitle = {Seminar IITM WS 23},
|
||||
date = {2024},
|
||||
doi = {10.2313/NET-2024-04-1\_16},
|
||||
url = {https://www.net.in.tum.de/fileadmin/TUM/NET/NET-2024-04-1/NET-2024-04-1_16.pdf}
|
||||
date = {2024},
|
||||
doi = {10.2313/NET-2024-04-1\_16},
|
||||
url = {https://www.net.in.tum.de/fileadmin/TUM/NET/NET-2024-04-1/NET-2024-04-1_16.pdf}
|
||||
}
|
||||
|
||||
@inproceedings{hoilandjorgensen2018xdp,
|
||||
author = {H{\o}iland-J{\o}rgensen, Toke and Brouer, Jesper Dangaard and Borkmann, Daniel and Fastabend, John and Herbert, Tom and Ahern, David and Miller, David},
|
||||
title = {The {eXpress} Data Path: Fast Programmable Packet Processing in the Operating System Kernel},
|
||||
author = {H{\o}iland-J{\o}rgensen, Toke and Brouer, Jesper Dangaard and Borkmann, Daniel and Fastabend, John and Herbert, Tom and Ahern, David and Miller, David},
|
||||
title = {The {eXpress} Data Path: Fast Programmable Packet Processing in the Operating System Kernel},
|
||||
booktitle = {Proceedings of the 14th International Conference on Emerging Networking Experiments and Technologies},
|
||||
series = {CoNEXT '18},
|
||||
pages = {54--66},
|
||||
series = {CoNEXT '18},
|
||||
pages = {54--66},
|
||||
publisher = {Association for Computing Machinery},
|
||||
location = {Heraklion, Greece},
|
||||
date = {2018},
|
||||
doi = {10.1145/3281411.3281443},
|
||||
url = {https://doi.org/10.1145/3281411.3281443}
|
||||
location = {Heraklion, Greece},
|
||||
date = {2018},
|
||||
doi = {10.1145/3281411.3281443},
|
||||
url = {https://doi.org/10.1145/3281411.3281443}
|
||||
}
|
||||
|
||||
@inproceedings{scholz2018ebpfpacketfiltering,
|
||||
author = {Scholz, Dominik and Raumer, Daniel and Emmerich, Paul and Kurtz, Alexander and Lesiak, Krzysztof and Carle, Georg},
|
||||
title = {Performance Implications of Packet Filtering with {Linux eBPF}},
|
||||
author = {Scholz, Dominik and Raumer, Daniel and Emmerich, Paul and Kurtz, Alexander and Lesiak, Krzysztof and Carle, Georg},
|
||||
title = {Performance Implications of Packet Filtering with {Linux eBPF}},
|
||||
booktitle = {2018 30th International Teletraffic Congress},
|
||||
series = {ITC 30},
|
||||
pages = {209--217},
|
||||
series = {ITC 30},
|
||||
pages = {209--217},
|
||||
publisher = {IEEE},
|
||||
location = {Vienna, Austria},
|
||||
date = {2018},
|
||||
doi = {10.1109/ITC30.2018.00039},
|
||||
url = {https://www.net.in.tum.de/fileadmin/bibtex/publications/papers/ITC30-Packet-Filtering-eBPF-XDP.pdf}
|
||||
location = {Vienna, Austria},
|
||||
date = {2018},
|
||||
doi = {10.1109/ITC30.2018.00039},
|
||||
url = {https://www.net.in.tum.de/fileadmin/bibtex/publications/papers/ITC30-Packet-Filtering-eBPF-XDP.pdf}
|
||||
}
|
||||
|
||||
@online{gbadamosi2024ebpfruntime,
|
||||
author = {Gbadamosi, Bolaji and Leonardi, Luigi and Pulls, Tobias and H{\o}iland-J{\o}rgensen, Toke and Ferlin-Reiter, Simone and Sorce, Simo and Brunstr{\"o}m, Anna},
|
||||
title = {The {eBPF} Runtime in the {Linux} Kernel},
|
||||
date = {2024-10-03},
|
||||
eprint = {2410.00026},
|
||||
author = {Gbadamosi, Bolaji and Leonardi, Luigi and Pulls, Tobias and H{\o}iland-J{\o}rgensen, Toke and Ferlin-Reiter, Simone and Sorce, Simo and Brunstr{\"o}m, Anna},
|
||||
title = {The {eBPF} Runtime in the {Linux} Kernel},
|
||||
date = {2024-10-03},
|
||||
eprint = {2410.00026},
|
||||
eprinttype = {arXiv},
|
||||
doi = {10.48550/arXiv.2410.00026},
|
||||
url = {https://arxiv.org/abs/2410.00026},
|
||||
urldate = {2026-05-15}
|
||||
doi = {10.48550/arXiv.2410.00026},
|
||||
url = {https://arxiv.org/abs/2410.00026},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@inproceedings{westphal2016bridgefiltering,
|
||||
author = {Westphal, Florian},
|
||||
title = {Bridge Filtering with {nftables}},
|
||||
author = {Westphal, Florian},
|
||||
title = {Bridge Filtering with {nftables}},
|
||||
booktitle = {Proceedings of Netdev 1.1},
|
||||
location = {Seville, Spain},
|
||||
date = {2016},
|
||||
url = {https://netdevconf.org/1.1/proceedings/papers/Bridge-filter-with-nftables.pdf},
|
||||
urldate = {2026-05-15}
|
||||
location = {Seville, Spain},
|
||||
date = {2016},
|
||||
url = {https://netdevconf.org/1.1/proceedings/papers/Bridge-filter-with-nftables.pdf},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@article{conti2016mitmsurvey,
|
||||
author = {Conti, Mauro and Dragoni, Nicola and Lesyk, Viktor},
|
||||
title = {A Survey of {Man In The Middle} Attacks},
|
||||
author = {Conti, Mauro and Dragoni, Nicola and Lesyk, Viktor},
|
||||
title = {A Survey of {Man In The Middle} Attacks},
|
||||
journaltitle = {IEEE Communications Surveys \& Tutorials},
|
||||
volume = {18},
|
||||
number = {3},
|
||||
pages = {2027--2051},
|
||||
date = {2016},
|
||||
doi = {10.1109/COMST.2016.2548426},
|
||||
url = {https://doi.org/10.1109/COMST.2016.2548426}
|
||||
volume = {18},
|
||||
number = {3},
|
||||
pages = {2027--2051},
|
||||
date = {2016},
|
||||
doi = {10.1109/COMST.2016.2548426},
|
||||
url = {https://doi.org/10.1109/COMST.2016.2548426}
|
||||
}
|
||||
|
||||
@article{nam2012arpmitm,
|
||||
author = {Nam, Seung Yeob and Jurayev, Sirojiddin and Kim, Seung-Sik and Choi, Kwonhue and Choi, Gyu Sang},
|
||||
title = {Mitigating {ARP} Poisoning-Based {Man-in-the-Middle} Attacks in Wired or Wireless {LAN}},
|
||||
author = {Nam, Seung Yeob and Jurayev, Sirojiddin and Kim, Seung-Sik and Choi, Kwonhue and Choi, Gyu Sang},
|
||||
title = {Mitigating {ARP} Poisoning-Based {Man-in-the-Middle} Attacks in Wired or Wireless {LAN}},
|
||||
journaltitle = {EURASIP Journal on Wireless Communications and Networking},
|
||||
volume = {2012},
|
||||
number = {1},
|
||||
eid = {89},
|
||||
date = {2012},
|
||||
doi = {10.1186/1687-1499-2012-89},
|
||||
url = {https://doi.org/10.1186/1687-1499-2012-89}
|
||||
volume = {2012},
|
||||
number = {1},
|
||||
eid = {89},
|
||||
date = {2012},
|
||||
doi = {10.1186/1687-1499-2012-89},
|
||||
url = {https://doi.org/10.1186/1687-1499-2012-89}
|
||||
}
|
||||
|
||||
@inproceedings{zhang2007portmirroring,
|
||||
author = {Zhang, Jian and Moore, Andrew W.},
|
||||
title = {Traffic Trace Artifacts due to Monitoring Via Port Mirroring},
|
||||
author = {Zhang, Jian and Moore, Andrew W.},
|
||||
title = {Traffic Trace Artifacts due to Monitoring Via Port Mirroring},
|
||||
booktitle = {2007 Workshop on End-to-End Monitoring Techniques and Services},
|
||||
series = {E2EMON '07},
|
||||
pages = {1--8},
|
||||
series = {E2EMON '07},
|
||||
pages = {1--8},
|
||||
publisher = {IEEE},
|
||||
date = {2007},
|
||||
doi = {10.1109/E2EMON.2007.375317},
|
||||
url = {https://www.cl.cam.ac.uk/research/srg/netos/papers/2007-zhang2007traffic.pdf},
|
||||
urldate = {2026-05-16}
|
||||
date = {2007},
|
||||
doi = {10.1109/E2EMON.2007.375317},
|
||||
url = {https://www.cl.cam.ac.uk/research/srg/netos/papers/2007-zhang2007traffic.pdf},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@inproceedings{durumeric2017httpsinterception,
|
||||
author = {Durumeric, Zakir and Ma, Zane and Springall, Drew and Barnes, Richard and Sullivan, Nick and Bursztein, Elie and Bailey, Michael and Halderman, J. Alex and Paxson, Vern},
|
||||
title = {The Security Impact of {HTTPS} Interception},
|
||||
author = {Durumeric, Zakir and Ma, Zane and Springall, Drew and Barnes, Richard and Sullivan, Nick and Bursztein, Elie and Bailey, Michael and Halderman, J. Alex and Paxson, Vern},
|
||||
title = {The Security Impact of {HTTPS} Interception},
|
||||
booktitle = {Proceedings of the Network and Distributed System Security Symposium},
|
||||
series = {NDSS '17},
|
||||
date = {2017},
|
||||
doi = {10.14722/ndss.2017.23456},
|
||||
url = {https://doi.org/10.14722/ndss.2017.23456}
|
||||
series = {NDSS '17},
|
||||
date = {2017},
|
||||
doi = {10.14722/ndss.2017.23456},
|
||||
url = {https://doi.org/10.14722/ndss.2017.23456}
|
||||
}
|
||||
|
||||
@inproceedings{waked2018tlsinterception,
|
||||
author = {Waked, Louis and Mannan, Mohammad and Youssef, Amr},
|
||||
title = {To Intercept or Not to Intercept: Analyzing {TLS} Interception in Network Appliances},
|
||||
author = {Waked, Louis and Mannan, Mohammad and Youssef, Amr},
|
||||
title = {To Intercept or Not to Intercept: Analyzing {TLS} Interception in Network Appliances},
|
||||
booktitle = {Proceedings of the 2018 {ACM Asia} Conference on Computer and Communications Security},
|
||||
series = {ASIACCS '18},
|
||||
pages = {399--412},
|
||||
series = {ASIACCS '18},
|
||||
pages = {399--412},
|
||||
publisher = {Association for Computing Machinery},
|
||||
location = {Incheon, Republic of Korea},
|
||||
date = {2018},
|
||||
doi = {10.1145/3196494.3196528},
|
||||
url = {https://doi.org/10.1145/3196494.3196528}
|
||||
location = {Incheon, Republic of Korea},
|
||||
date = {2018},
|
||||
doi = {10.1145/3196494.3196528},
|
||||
url = {https://doi.org/10.1145/3196494.3196528}
|
||||
}
|
||||
|
||||
@article{decarnedecarnavalet2023tlsinterception,
|
||||
author = {de Carn{\'e} de Carnavalet, Xavier and van Oorschot, Paul C.},
|
||||
title = {A Survey and Analysis of {TLS} Interception Mechanisms and Motivations},
|
||||
author = {de Carn{\'e} de Carnavalet, Xavier and van Oorschot, Paul C.},
|
||||
title = {A Survey and Analysis of {TLS} Interception Mechanisms and Motivations},
|
||||
journaltitle = {ACM Computing Surveys},
|
||||
volume = {55},
|
||||
number = {13s},
|
||||
articleno = {269},
|
||||
pages = {1--40},
|
||||
date = {2023},
|
||||
doi = {10.1145/3580522},
|
||||
url = {https://doi.org/10.1145/3580522}
|
||||
volume = {55},
|
||||
number = {13s},
|
||||
articleno = {269},
|
||||
pages = {1--40},
|
||||
date = {2023},
|
||||
doi = {10.1145/3580522},
|
||||
url = {https://doi.org/10.1145/3580522}
|
||||
}
|
||||
|
||||
@manual{ieee8021q2022,
|
||||
author = {{IEEE}},
|
||||
title = {{IEEE Standard for Local and Metropolitan Area Networks--Bridges and Bridged Networks}},
|
||||
author = {{IEEE}},
|
||||
title = {{IEEE Standard for Local and Metropolitan Area Networks--Bridges and Bridged Networks}},
|
||||
organization = {IEEE},
|
||||
type = {IEEE Std 802.1Q-2022},
|
||||
date = {2022-12-22},
|
||||
url = {https://standards.ieee.org/ieee/802.1Q/10323/},
|
||||
urldate = {2026-05-16}
|
||||
type = {IEEE Std 802.1Q-2022},
|
||||
date = {2022-12-22},
|
||||
url = {https://standards.ieee.org/ieee/802.1Q/10323/},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@inproceedings{perlman1985spanningtree,
|
||||
author = {Perlman, Radia},
|
||||
title = {An Algorithm for Distributed Computation of a Spanningtree in an Extended {LAN}},
|
||||
author = {Perlman, Radia},
|
||||
title = {An Algorithm for Distributed Computation of a Spanningtree in an Extended {LAN}},
|
||||
booktitle = {Proceedings of the Ninth Symposium on Data Communications},
|
||||
series = {SIGCOMM '85},
|
||||
pages = {44--53},
|
||||
series = {SIGCOMM '85},
|
||||
pages = {44--53},
|
||||
publisher = {Association for Computing Machinery},
|
||||
location = {Whistler Mountain, British Columbia, Canada},
|
||||
date = {1985},
|
||||
doi = {10.1145/319056.319004},
|
||||
url = {https://doi.org/10.1145/319056.319004}
|
||||
location = {Whistler Mountain, British Columbia, Canada},
|
||||
date = {1985},
|
||||
doi = {10.1145/319056.319004},
|
||||
url = {https://doi.org/10.1145/319056.319004}
|
||||
}
|
||||
|
||||
@online{linuxkernelnetworkingdocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Networking --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/index.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Networking --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/index.html},
|
||||
urldate = {2026-04-18}
|
||||
}
|
||||
|
||||
@online{linuxkernelskbuffdocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {struct sk\_buff --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/skbuff.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {struct sk\_buff --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/skbuff.html},
|
||||
urldate = {2026-04-18}
|
||||
}
|
||||
|
||||
@online{linuxkernelbridgedocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Ethernet Bridging --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/bridge.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Ethernet Bridging --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/bridge.html},
|
||||
urldate = {2026-04-18}
|
||||
}
|
||||
|
||||
@online{linuxkernelswitchdevdocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Ethernet switch device driver model (switchdev) --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://www.kernel.org/doc/html/latest/networking/switchdev.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Ethernet switch device driver model (switchdev) --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://www.kernel.org/doc/html/latest/networking/switchdev.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{linuxkernelflowtabledocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Netfilter's Flowtable Infrastructure --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/nf_flowtable.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Netfilter's Flowtable Infrastructure --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/nf_flowtable.html},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@online{linuxkernelscalingdocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Scaling in the Linux Networking Stack --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/scaling.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Scaling in the Linux Networking Stack --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://docs.kernel.org/networking/scaling.html},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@online{linuxkerneltracepointsdocs,
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Using the Linux Kernel Tracepoints --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://www.kernel.org/doc/html/latest/trace/tracepoints.html},
|
||||
author = {{The Linux Kernel Documentation Authors}},
|
||||
title = {Using the Linux Kernel Tracepoints --- The Linux Kernel documentation},
|
||||
year = {2026},
|
||||
url = {https://www.kernel.org/doc/html/latest/trace/tracepoints.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{man7packet,
|
||||
author = {{Linux man-pages project}},
|
||||
title = {packet(7) --- Linux manual page},
|
||||
date = {2025-09-21},
|
||||
url = {https://man7.org/linux/man-pages/man7/packet.7.html},
|
||||
author = {{Linux man-pages project}},
|
||||
title = {packet(7) --- Linux manual page},
|
||||
date = {2025-09-21},
|
||||
url = {https://man7.org/linux/man-pages/man7/packet.7.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{man7tcbpf,
|
||||
author = {{Linux man-pages project}},
|
||||
title = {tc-bpf(8) --- Linux manual page},
|
||||
date = {2025-08-08},
|
||||
url = {https://man7.org/linux/man-pages/man8/tc-bpf.8.html},
|
||||
author = {{Linux man-pages project}},
|
||||
title = {tc-bpf(8) --- Linux manual page},
|
||||
date = {2025-08-08},
|
||||
url = {https://man7.org/linux/man-pages/man8/tc-bpf.8.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{man7bridge,
|
||||
author = {{Linux man-pages project}},
|
||||
title = {bridge(8) --- Linux manual page},
|
||||
date = {2012-08-01},
|
||||
url = {https://man7.org/linux/man-pages/man8/bridge.8.html},
|
||||
author = {{Linux man-pages project}},
|
||||
title = {bridge(8) --- Linux manual page},
|
||||
date = {2012-08-01},
|
||||
url = {https://man7.org/linux/man-pages/man8/bridge.8.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{man7iplink,
|
||||
author = {{Linux man-pages project}},
|
||||
title = {ip-link(8) --- Linux manual page},
|
||||
date = {2012-12-13},
|
||||
url = {https://man7.org/linux/man-pages/man8/ip-link.8.html},
|
||||
author = {{Linux man-pages project}},
|
||||
title = {ip-link(8) --- Linux manual page},
|
||||
date = {2012-12-13},
|
||||
url = {https://man7.org/linux/man-pages/man8/ip-link.8.html},
|
||||
urldate = {2026-05-16}
|
||||
}
|
||||
|
||||
@online{nftableshooks,
|
||||
author = {{The nftables Project}},
|
||||
title = {Netfilter Hooks},
|
||||
year = {2023},
|
||||
url = {https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks},
|
||||
author = {{The nftables Project}},
|
||||
title = {Netfilter Hooks},
|
||||
year = {2023},
|
||||
url = {https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@online{nftablesbridgefiltering,
|
||||
author = {{The nftables Project}},
|
||||
title = {Bridge Filtering},
|
||||
year = {2021},
|
||||
url = {https://wiki.nftables.org/wiki-nftables/index.php/Bridge_filtering},
|
||||
author = {{The nftables Project}},
|
||||
title = {Bridge Filtering},
|
||||
year = {2021},
|
||||
url = {https://wiki.nftables.org/wiki-nftables/index.php/Bridge_filtering},
|
||||
urldate = {2026-05-15}
|
||||
}
|
||||
|
||||
@online{nftables_manpage,
|
||||
title = {nft(8) -- Administration Tool of the nftables Framework
|
||||
for Packet Filtering and Classification},
|
||||
author = {{The Netfilter Project}},
|
||||
organization = {The Netfilter Project},
|
||||
year = {2026},
|
||||
url = {https://netfilter.org/projects/nftables/manpage.html},
|
||||
note = {Accessed: 2026-08-08}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user